Privacy Policy
Last updated: 23 August 2026
We collect what we need to record an unlock, bill you for it, and pay the publisher. We do not sell personal information, and publishers see only what they need to run their own site.
1. Who this covers
This policy applies to readers who unlock articles and to publishers who sell them. Where something applies to only one group, we say so.
Paperwall is the controller of the personal information described here. Publishers are separately responsible for their own sites, their own Ghost installations, and any data they collect themselves, which their own privacy policy covers.
2. What we collect
2.1 Reader account data
- Your email address.
- Your name or display name, if you give us one.
- Authentication data: sign-in tokens, session identifiers and login timestamps.
- Preferences and settings you choose.
2.2 Unlock history
- Which articles you unlocked, and when.
- The publisher and site each unlock belongs to.
- Article metadata: title, URL, and the ticket cost at the time of unlock.
- Whether the unlock succeeded, failed, or is still pending.
2.3 Billing records
- Your ticket balance and the transactions that make it up.
- Your billing cycle dates and the combined charge raised for each cycle.
- Amounts charged, currency, and the status of each charge.
- Receipts and invoices.
- Card details supplied by Stripe: the card brand, its last four digits, its expiry month and year, and the cardholder name. We hold these encrypted, and use the expiry date to warn you before a card lapses mid-cycle.
- A Stripe customer reference linking your account to your payment method.
- Tax-relevant information such as country of purchase, where we need it.
We do not store full card numbers, security codes or bank credentials. Those go directly to Stripe, our payment processor, which handles them under its own security standards and privacy policy. We hold only the reference and the card summary described above.
2.4 Refund and cancellation records
- Which unlocks were cancelled or refunded, when, by whom, and at what point in the cycle.
- Ticket credit issued to you as a result of a refund.
- Chargeback and dispute records, including evidence submitted to the payment processor.
2.5 Device, log and analytics data
- IP address, browser and device type, operating system, and referring page.
- Server logs of requests to Paperwall, with timestamps and error traces.
- Product analytics showing which pages and flows you use, so we can find where the unlock flow breaks.
- Cookies and similar technologies, covered by the Cookie Policy.
2.6 Publisher data
- Account and contact details for the publisher and its admins.
- Site details: domain, Ghost configuration and integration credentials.
- Pricing configuration and article catalogue.
- Payout details, balances, and any tax or identity information a payout requires.
2.7 Ratings, votes and notes
If you rate an article, vote on it or leave a note, we store that against your account and the article. Aggregated scores are shown to other readers, and they can affect what an article costs in tickets. Other readers cannot tell which rating was yours. The publisher of the article can: their site report lists individual ratings against the reader ID that gave them, so a publisher can see how a particular reader rated a particular article.
2.8 Messages you send us
Anything you send through the contact form or by email, including attachments to a support request or dispute.
3. Why we use it
- To run the service: creating accounts, delivering unlocks, maintaining the ledger.
- To bill readers and pay publishers: accruing unlocks against your account, raising your periodic charge, calculating the payout pool and each publisher's share, and applying deductions.
- To handle refunds and disputes: including responding to a chargeback with transaction records, unlock logs, receipts and article metadata.
- To provide support: answering questions and investigating problems.
- To prevent fraud and abuse: detecting stolen cards, unlock farming, rating manipulation and payment avoidance.
- To improve Paperwall: understanding which flows work, in aggregate where possible.
- To meet legal obligations: tax, accounting, and lawful requests.
- To send service messages: receipts, upcoming and failed charges, and account or policy notices. Marketing email, if we send any, is opt-in and always unsubscribable.
Where the law requires a legal basis, such as under the GDPR, ours is: performing our contract with you for the account and the unlocks; our legitimate interests in security, fraud prevention and product improvement; legal obligation for tax and accounting; and consent for optional analytics or marketing, which you can withdraw.
4. What publishers can see
Publishers get what they need to run their business, not your full Paperwall history. Readers are identified to publishers by a reader ID, an internal identifier that is not your email address or your name. For their own site, a publisher can see:
- which of their articles were unlocked, when, and by which reader ID;
- the ticket cost of each unlock and its transaction status;
- refund and cancellation records for their own transactions;
- individual ratings, votes and notes on their articles, against the reader ID that left them;
- their site balance and aggregate figures such as total visits, ratings and reads.
Publishers cannot see:
- your email address, name or account credentials;
- your unlock history on other publishers' sites;
- your ticket balance or your total spend across Paperwall;
- your payment method details.
A reader ID is stable across your unlocks on a given site, so a publisher can tell that the same reader returned, and can build a picture of that reader's activity on their site over time. Treat it as pseudonymous rather than anonymous: it does not name you, but it does link your activity together. If you contact a publisher directly, or their site collects your details separately, they may be able to connect that to your reader ID themselves.
Publishers are independently responsible for what they do with reader information they receive. Where a publisher uses it for their own purposes, such as marketing, they act as their own controller under their own privacy policy.
5. Who else we share it with
- Stripe, our payment processor, to take payment, store your card, run publisher payouts and handle disputes.
- Infrastructure and hosting providers, to run the servers, database and CDN behind Paperwall.
- Analytics and error-tracking providers, to diagnose and improve the service.
- Email providers, to send receipts and service messages.
- Professional advisers, where accountants or lawyers need it to advise us.
- Authorities, where we are legally required to disclose, or to protect rights, safety or the integrity of the service.
- An acquirer, if Paperwall is merged, acquired or sold, subject to this policy continuing to apply.
We do not sell your personal information.
6. Where your data is held
Paperwall operates from Canada, and our providers may process data in Canada, the United States and the European Union. Where we transfer personal information across borders we rely on appropriate safeguards, such as standard contractual clauses, where the law requires them.
7. How long we keep it
- Transaction, unlock, refund and payout records: kept for as long as tax and accounting law requires, typically seven years from the transaction. These are financial records, so we keep them after an account closes.
- Account data: kept while your account is open, and for a reasonable period afterwards to handle disputes and legal claims.
- Logs and analytics: kept for a shorter period, typically up to 24 months.
- Support messages: kept for as long as needed to resolve the issue and to maintain a record of it.
When we no longer need personal information we delete or anonymise it.
8. Security
We use encryption in transit, restricted internal access, and third-party processors for payment data so that card details never reach our systems. No service is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator where the law requires it.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you, and get a copy;
- correct information that is wrong or out of date;
- delete your information, subject to records we must keep for tax and legal reasons;
- object to or restrict certain processing, including analytics;
- withdraw consent where we relied on it;
- port your data to another service;
- complain to your data protection authority.
You can do some of this yourself from your account. For anything else, email privacy@paperwall.io and we will respond within the time the law allows, usually within a few days. We may need to verify your identity first.
Where your request concerns data a publisher holds about you on their own site, we will point you to that publisher, since we cannot act on their behalf.
10. Children
Paperwall is not intended for children. We do not knowingly collect personal information from anyone below the age at which they can consent to online services where they live. Tell us if you believe a child has given us information and we will delete it.
11. Changes to this policy
We update this page when our practices change, and the date at the top shows when we last did. For material changes we notify you through the service or by email.
12. Contact
Email privacy@paperwall.io for privacy questions or to exercise your rights, or use the contact form. We are a small team in the west end of Toronto, Canada.